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AMENDMENTS TO THE CLAIMS 

1. (Currently Amended) A method for protecting an operating system, comprising: 
determining integrity data associat e d with for an operating system binary, wherein the 

integrity data enables detection of a modification to the operating system binary; and 

modifying a kernel with the integrity data, wherein the kernel is operable to employ the 
integrity data to detect the modification to the operating system binary. 

2. (Original) The method of claim 1, wherein the integrity data further comprises at 
least one of a digital signature, and a hash associated with the operating system binary. 

3. (Original) The method of claim 2, wherein the hash further comprises at least one a 
message digest, and a Secure Hash Algorithm (SHA). 

4. (Original) The method of claim 1 , wherein the modifying the kernel further 
comprises: 

storing the integrity data in a data store; and 
embedding the data store into the kernel. 

5. (Original) The method of claim 4, wherein embedding the data store in the kernel 
further comprises at least one of digitally signing the data store, and encrypting the data store. 

6. (Original) The method of claim 1, further comprising generating an operating 
system image based in part on the modified kernel and the operating system user level binary, 
wherein the operating system image comprises at least one of creating an archive file, a compressed 
file, and a Cabinet (CAB) file. 

7. (Original) The method of claim 1, wherein the operating system binary further 
comprises at least one of an OS user level binary, and the kernel. 

8. (Currently Amended) A method for protecting an operating system, comprising; 
generating a first integrity data as s ociat e d with for an operating system binary; 
modifying an operating system kernel with the first integrity data; 
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receiving a request associated with the operating system binary; 

retrieving the first integrity data a ss ociated with for the operating system binary; 

determining if the first integrity data indicates tampering of the operating system binary; 

and 

performing a tamper detection action if the first integrity data indicates tampering of the 
operating system binary. 

9. (Original) The method of claim 8, wherein receiving the request further comprises 
receiving at least one of a read action, an execute operation, and an install request. 

1 0. (Original) The method of claim 8, wherein performing the tamper detection action 
further comprises at least one of providing a tamper detection message, and quarantining the 
operating system binary. 

1 1 . (Original) The method of claim 8, wherein the first integrity data further comprises 
at least one of a digital signature, and a hash associated with the operating system binary. 

12. (Original) The method of claim 11, wherein the hash further comprises at least one a 
message digest, and a Secure Hash Algorithm (SHA). 

13. (Original) The method of claim 8, wherein modifying the operating system kernel 
with the first integrity data further comprises storing the first integrity data in at least one of a 
database, a file, and a program. 

14. (Original) The method of claim 8, wherein modifying the operating system kernel 
further comprises associating the first integrity data with the operating system kernel. 

15. (Original) The method of claim 14, where associating the first integrity data with the 
operating system kernel further comprises digitally signing the first integrity data with a digital key 
associated with the operating system kernel. 
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16. (Currently Amended) The method of claim 8, wherein determining if the first 
integrity data indicates tampering of the operating system binary further comprises: 

determining a second integrity data a s sociat e d with for the operating system binary; 
determining if the first integrity data is substantially different from the second integrity 

data; and 

indicating tampering of the operating system binary if the first integrity data is 
substantially different from the second integrity data. 

17. (Original) The method of claim 16, wherein determining if the first integrity data is 
substantially different from the second integrity data further comprises comparing the second 
integrity data to the first integrity data. 

18. (Currently Amended) A method for protecting an operating system, comprising: 
receiving a request associated with an operating system binary; 

retrieving integrity data associat e d with for the operating system binary; and 
performing a tamper detection action if the integrity data indicates tampering of the 
operating system binary. 

1 9. (Original) The method of claim 1 8, wherein receiving the request further comprises 
receiving at least one of a read action, an execute operation, and an install request. 

20. (Original) The method of claim 1 8, wherein performing the tamper detection action 
further comprises at least one of providing a tamper detection message, and quarantining the 
operating system binary. 

2 1 . (Currently Amended) The method of claim 1 8, wherein determining if the integrity 
data indicates tampering of the operating system binary further comprises: 

determining another integrity data associated with for the operating system binary; 
determining if the other integrity data is substantially different from the retrieved 
integrity data; and 
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indicating tampering of the operating system binary if the other integrity data is 
substantially different from the retrieved integrity data. 

22. (Currently Amended) A computer-readable medium having computer-executable 
components for protecting an operating system, comprising: 

a data store configured to receive and store a first integrity data, wherein the first 
integrity data is as s ociat e d with for an operating system binary; and 

a tamper detection component, coupled to the data store, that is arranged to perform 
actions, including: 

receiving a request to examine an operating system binary; 

retrieving the first integrity data a ss ociated with for the operating system 

binary; 

determining if the first integrity data indicates tampering of the operating 

system binary; and 

performing a tamper detection action if the first integrity data indicates 
tampering of the operating system binary. 

23. (Original) The computer-readable medium of claim 22, wherein the computer- 
executable components are associated with an operating system kernel. 

24. (Original) The computer-readable medium of claim 22, wherein performing the 
tamper detection action further comprises at least one of providing a tamper detection message, and 
quarantining the operating system binary. 

25. (Original) The computer-readable medium of claim 22, wherein the first integrity 
data further comprises at least one of a digital signature, and a hash associated with the operating 
system binary. 

26. (Original) The computer-readable medium of claim 22, wherein the operating 
system binary further comprises at least one of an OS user level binary, and a kernel. 
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27. (Currently Amended) The computer-readable medium of claim 22, wherein 
determining if the first integrity data indicates tampering of the operating system binary further 
comprises: 

determining a second integrity data as s ociat e d with for the operating system binary; 
determining if the first integrity data is substantially different from the second integrity 

data, and 

indicating tampering of the operating system binary if the first integrity data is 
substantially different from the second integrity data. 

28. (Original) The computer-readable medium of claim 22, wherein the second integrity 
data further comprises at least one of a digital signature, and a hash associated with the operating 
system binary. 

29. (Currently Amended) An apparatus for protecting an operating system, comprising: 
means for receiving a request to examine an operating system binary; 

means for retrieving a first integrity data associat e d with for the operating system binary; 
means for determining a second integrity data a ss ociated with for the operating system 

binary; and 

means for determining if the first integrity data is substantially different from the second 
integrity data, and if the first integrity data is substantially different from the second integrity data, a 
means for performing a tamper detection action. 
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